logo

Showboat Malware Targets Telecoms with Stealth Techniques

ID: a85ef8d3-b121-5d86-b9bc-2b90399bf143

STIX ID: report--a85ef8d3-b121-5d86-b9bc-2b90399bf143

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-19

Date Updated: 2026-06-22

...
...

Showboat is a modular Linux post-exploitation framework attributed to Chinese actors that has targeted Middle Eastern telecom companies since mid-2022. It employs advanced stealth techniques—such as retrieving C source from Pastebin and compiling it at runtime—and remained undetected by antivirus engines until detection in April 2026, posing a significant risk to critical communications infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.